Next Generation Partners

Firms To Watch: Data protection

Data protection in Australia

Atmos

With a presence in both Australia and New Zealand, Atmos is a newly established cyber, privacy, and digital risk boutique firm, with a team comprised of Richard Berkahn, Alec Christie, Reece Corbett-Wilkins, and John Moran, all former partners at Clyde & Co LLP.

Gilchrist Connell

Since its inception in 2021, the cyber practice at Gilchrist Connell has grown rapidly under the leadership of Nitesh Patel, who brings to bear over 15 years of experience in the field of technology, privacy, data security, incident response and cyber insurance issues.

Allens

Allens‘ team collaborates with clients to ensure compliance across all stages of the data lifecycle, from creation and collection to storage, security, use, exchange, commercialisation, retention, and de-identification or disposal. The team acts for leading names in the technology and financial services sectors. In Sydney, Gavin Smith is co-practice leader and heads the firm’s technology, media and telecommunications group, while co-head Valeska Bloch leads the cyber practice, with expertise across transactional, regulatory, governance, risk, and incident response matters in the cybersecurity, technology, and data spheres. David Rountree advises clients in highly regulated industries on innovative commercial use of technology and data. Isabelle Guyot, who was promoted to partner in July 2025, is also noted.

Praxisleiter:

Gavin Smith; Valeska Bloch


Weitere Kernanwälte:

David Rountree; Isabelle Guyot


Referenzen

‚Gavin Smith and Isabelle Guyot both take the time to understand our business and product and provide tailored advice that helps us navigate a complex (and changing) regulatory environment.‘

‚The kind of service you hope for from a top tier firm. Collaborative, expert, pragmatic.‘

‚Valeska Bloch is a true thought leader – highly experienced, insightful and accessible.‘

Kernmandanten

Uber


Insurance Group Limited


TPG Telecom


Highlight-Mandate


  • Providing ongoing and regular advice to Uber in respect of strategic privacy, data and technology matters arising in connection with the launch and operation of its products, services and application features in Australia.
  • Advising TPG in connection with the reforms to telecommunications regulations and the Security of Critical Infrastructure Act.

Ashurst

Ashurst‘s data protection and cyber security team combines legal, risk and strategic expertise to support its substantial client roster in critical moments, assisting with privacy, cybersecurity, regulatory compliance, AI, and risk advisory. Geoff McGrath co-leads the team from Sydney and is an expert in technology, data, privacy and digital regulation, providing guidance on high-stakes matters. Melbourne-based Emma Butler, also a co-lead, is a digital economy specialist with experience in complex technology transactions, advising on digital transformation, strategic outsourcing, cloud services, data commercialisation and AI adoption. Clare Doneley is an expert in privacy, cybersecurity and critical infrastructure security. Sashini Walpola is known for her strategic counsel to corporates and government agencies on complex data, privacy and cybersecurity issues. Jarred Gerson is also a key member of the team.

Praxisleiter:

Emma Butler; Geoff McGrath


Weitere Kernanwälte:

Clare Doneley; Andrew Craig; Sashini Walpola; Erin Kirker; Jarred Gerson


Referenzen

‚Emma Butler and Erin Kirker understand the nature of our business and its complexity – they are commercial and are able to suggest practical ways of moving forward.‘

‚Emma Butler and her team provide exceptional service – they take the time to understand their clients‘ businesses and tailor their solutions. They have understood our business at a deep level and have become our trusted partners in the growth of our business. Their billing model is great.‘

‚The Ashurst team provide helpful, succinct commercial advice. It is a relief to call them and know that they are so across the issue. They never up-sell and are well and truly trusted advisers.‘

Kernmandanten

.au Domain Administration Limited


7-Eleven Stores Pty Ltd


AGL Energy Limited


AIA Australia Limited


ANZ Banking Group


Bank of Queensland


Carnival


City Of Melbourne


Commonwealth Government


Compare the Market


Earlypay Exchange


estateXchange


Focus Brands


Government of Western Australia


Guest Group


Henley Arch


H.R.L. Morrison & Co Limited


Judo Capital Holdings Ltd


Lend Lease Australia


KVD Singapore Pte. Ltd.


Macquarie Technology Group


Meta (formerly Facebook)


NBN Co Limited


Next Payments


NSW Government


Queensland Government


SingTel Optus Pty Limited


Standards Australia Limited


SUBCO Operations | Soda


The Quantium Group


Titan Neuroscience Research


Tuvalu Telecommunications Corporation


Verizon Australia


Vicinity Limited


Victoria Government


Westpac


Whitehaven Coal Mining Ltd


Woolworths


Highlight-Mandate


  • Advising a global digital platform on the application of Australian laws to AI across multiple sectors.
  • Representing a global tech company in a Federal Court challenge against the Australian eSafety Commissioner over takedown orders under the Online Safety Act 2021.
  • Advising a major Australian superannuation fund affected by the recent coordinated cyber-attack on the Australian superannuation sector, providing strategic legal guidance on incident response, data breach notification obligations, and regulatory engagement with bodies including the OAIC, ASIC, and APRA.

Clayton Utz

Clayton Utz advises clients on complex cross-jurisdictional regulatory frameworks, AI governance, data transfers and protection, privacy challenges, cyber breach responses, and emerging cyber threats, cutting across multiple industries. Brenton Steenkamp brings to the team over 20 years’ experience advising global clients on cyber and data breach investigations. Ken Saurajen, who assumed the role of head of the national technology practice in July 2025, has a strong track record in advising on some of the market’s most significant, high-profile, and complex technology, privacy, and cyber transactions. Both are based in Sydney.

Praxisleiter:

Ken Saurajen; Brenton Steenkamp


Weitere Kernanwälte:

Eleanor Dickens; Simon Newcomb; Monique Azzopardi; Christina Graves


Referenzen

‚The team has market leading expertise in the government, public sector and data protection and cyber security practices. In addition to technical excellence, they are approachable, and it is always a positive experience working with the team.‘

‚Eleanor Dickens and Simon Newcomb are outstanding professional and partners in their respective fields.‘

‚Responses are always delivered on time as necessary and without extending the scope observations regarding additional issues that could be explored are noted.‘

Kernmandanten

Alipay


Australian Digital Health Agency


Barclay’s Bank


BP


Brisbane Airport Corporation


Brisbane City Council


Commonwealth Bank of Australia


Discover


Single Digital Patient Record Implementation Authority


Sunshine Coast Council


Universities of Adelaide and South Australia; new Adelaide University


Verifone Yamaha


Highlight-Mandate


  • Assisting the University of Adelaide, University of South Australia and the new Adelaide University on a complex, multi-party data migration project critical to establishing Adelaide University.
  • Advising the SDPR Implementation Authority on the rollout of NSW’s state-wide electronic health record system, including integration with private hospitals and health facilities.
  • Advising the ADHA on a suite of procurements for the modernisation of the My Health Record system, including infrastructure modernisation, enhanced data interoperability, and system integration across the health sector.

Corrs Chambers Westgarth

Noted for its ‘excellent team’, Corrs Chambers Westgarth is a leader in data protection and cyber security. The firm has experience advising Australia’s largest acquirers and users of data across the financial services, government, technology, energy, resources, and retail sectors. James North leads the team from Sydney and heads the TMT practice. Eugenia Kolivos focuses on data protection and IP matters, Arvind Dixit has a focus on data protection, privacy and cyber risk resilience, and Michael Do Rozario advises on privacy, information governance, and cyber-crime, while Frances Wheelahan’s expertise in transactions and matters related to the commercialisation of intellectual property and technology provides the team with valuable balance.

Praxisleiter:

James North


Weitere Kernanwälte:

Eugenia Kolivos; Michael Do Rozario; Arvind Dixit; Frances Wheelahan; Philip Catania


Referenzen

‚Excellent team. Very well informed and up to date. At the cutting edge of new developments and never need to catch up. Courteous and easy to work with. Smart and effective.‘

‚James North is a true leader of his team. Keeps things moving and always alert. Highly intelligent.‘

‚The team is responsive and provides sound commercial advice. It is a top tier firm in this area and it lives up to the billing.‘

Kernmandanten

Genea IVF


Western Sydney University


Bunnings and Kmart


NSW Government


Kyocera


Oxfam


 


Highlight-Mandate


  • Advising Western Sydney University on a complex cyber incident, including engagement with regulatory bodies, coordination of technical experts, managing risk assessments and notifications, and securing an interim injunction against suspected threat actors and unauthorised use of stolen data.
  • Acting in the OAIC investigation into Bunnings and Kmart’s use of facial recognition technology.
  • Acting for Genea, a leading IVF and fertility clinic, following its February 2025 data breach.

Gilbert + Tobin

Established as a technology and telecommunications specialist law firm, Gilbert + Tobin is recognised for providing ‘exceptional advice and support’ through its data protection and cyber security team. The team manages issues across the full data lifecycle, considering numerous commercial factors, and particularly stands out for its advice to leading financial institutions and household names in the technology sector. Michael Williams leads the team in Sydney and is an IP litigator with over 25 years’ trial experience, with a focus on digital technologies. Melissa Fai, Simon Burns, and Tim Gole also contribute expertise in privacy, cyber, AI, IT, and commercial arrangements.

Praxisleiter:

Michael Williams


Weitere Kernanwälte:

Tim Gole; Melissa Fai; Simon Burns; Emilie Williams; Jen Bradley


Referenzen

‚Gilbert and Tobin provided our organisation with exceptional advice and support. They understood our AI ambitions and expertly navigated the complex cyber, data security and IP risks.‘

‚The lawyers I’ve dealt with at Gilbert and Tobin have all been extremely competent. I love that they have integrity with their diversity, reconciliation and accessibility practices. I think this makes them a standout compared to other firms.‘

‚Extremely helpful, efficient and practical legal advice.‘

Kernmandanten

Telstra


Football Australia Limited


Lift Shop


Department of Customer Service/ Service NSW


BCI Media Group


Microsoft


PricewaterhouseCoopers Australia


Westpac Banking Corporation


Australian Payments Plus


Highlight-Mandate


  • Represented Microsoft on various technology and digital policy and compliance issues associated with Microsoft’s hyperscale cloud platform, as well as its social media and gaming businesses.
  • Assisted Telstra on its AU$700m AI joint venture with Accenture to rapidly accelerate Telstra’s data and AI roadmap to further extend its network leadership.
  • Counselling Lift Shop in proceedings on appeal to the Full Court of the Federal Court of Australia in relation to additional damages, breach of copyright and breach of confidence where a former employee had left the client for a competitor and was alleged to have taken confidential information valuable to the competitor.

King & Wood Mallesons

King & Wood Mallesons’ cyber and data security team acts on major cyber, ransomware and privacy incidents, and advises boards on governance and responsibilities in a heightened regulatory environment, with a high-profile client roster that includes well-known names in the financial, technology and social media spaces. Cheng Lim leads the cyber incident response team from Melbourne. Patrick Gunning is a leading privacy and data protection lawyer, Michael Swinson advises on digital platforms and emerging technologies, and Kirsten Bowe specialises in IT, data protection, AI and intellectual property matters. Kendra Fouracre is also noted as being a valuable member of the team, with expertise spanning AI, privacy law and regulatory compliance.

Praxisleiter:

Cheng Lim


Weitere Kernanwälte:

Patrick Gunning; Michael Swinson; Kirsten Bowe; Kendra Fouracre


Referenzen

‚KWM’s team, led by Cheng Lim, are the best cyber legal advisors in Australia. This team brings real nuance to every client, supporting legally-sound, risk-based decision-making based on their experience working with crisis clients across several industries including healthcare, insurance, government, and finance.‘

‚Cheng Lim and his team are consummate professionals who work in partnership with their clients, and other advisors.‘

‚Cheng Lim takes a consultative approach to crisis management and advisory, and has shaped a culture in his team that reinforces the importance of partnership with clients and other advisors. Cheng’s advice is designed to help clients navigate complex decision-making under duress which distinguishes him from other law firms and other partners in this space.‘

Kernmandanten

The World Bank


Medibank Private


BHP


Latitude Financial Services


St Vincent’s Health Australia


Telstra


Canva


Highlight-Mandate


Baker McKenzie

Baker McKenzie‘s global data and cyber group advises on complex data challenges at both national and multi-jurisdictional levels. The team is co-led from Sydney by Adrian Lawrence, who is well versed in issues across the digital, data and technology sectors; Anne Petterd, a key member of the IPTech group; technology and cybersecurity litigation expert Ryan Grant; and Paul Forbes, who handles technology-related disputes. They are supported by Simone Blackadder and Jarrod Bayliss-McCulloch. The group’s expertise assists clients ranging from household names to start-ups. Toby Patten departed in May 2025.

Praxisleiter:

Adrian Lawrence; Anne Petterd; Ryan Grant; Paul Forbes


Weitere Kernanwälte:

Caitlin Whale; Simone Blackadder; Jarrod Bayliss-McCulloch


Referenzen

‚Genuinely international team with the ability to address the nuances of the given jurisdictions. This is a rare quality, as there are obvious similarities in many data protection regimes and less obvious but nevertheless very important differences.‘

‚Adrian Lawrence stands out for his very knowledgeable and pragmatic approach.‘

‚Ryan Grant and Paul Forbes of Baker McKenzie lead a practice that is distinguished by its deep expertise in technology, cybersecurity, and complex commercial litigation.‘

Kernmandanten

Zoe Lee McClure & Cihan Solbudak


Posco Australia Pty Ltd


Highlight-Mandate


  • Acting for Zoe Lee McClure and Cihan Solbudak as lead applicants in the class action commenced against Medibank Private Limited on behalf of individuals who were affected by the Medibank data breach in October 2022.
  • Acting for Posco Australia Pty Ltd in a dispute with Yancoal over a payment that was made to a nefarious actor.

Hall & Wilcox

Hall & Wilcox‘s team advises on cyber incidents, privacy compliance, and strategic data protection matters. Eden Winokur and Alison Baker co-head the team from Sydney and Melbourne, respectively. Winokur specialises in the full spectrum of cyber risk issues, acting on major Australian and international cyber and data breach matters, while Baker brings to bear over 20 years’ experience advising public and private clients on compliance with the Privacy Act 1988 and broader data protection law. Zeng He focuses on information law, privacy, and digital transformation projects. John Gray, a senior corporate and commercial partner specialising in digital technology and IP law, and Iona Goodwin are also noted.

Praxisleiter:

Eden Winokur; Alison Baker


Weitere Kernanwälte:

Zeng He; John Gray; Iona Goodwin; Brigitte Gasson


Referenzen

‚Expert cyber knowledge. Understand the needs of insurers very well. Great soft skills. Communicate well with insureds.‘

‚Extremely responsive. Partner very involved.‘

‚The strength of Hall & Wilcox’s data protection and cyber security practice is the quality of its staff. Led by Eden Winokur, the team has more soft skills and interpersonal skills than any other law firm in this area – without compromising on the quality of their legal knowledge.‘

Maddocks

Maddocks’ data, privacy and cyber team is led by three prominent partners. In Canberra, Katherine Armytage advises Commonwealth agencies and corporates, drawing on substantial ICT experience when addressing data protection and security issues. Sydney-based Sonia Sharma is privacy and cyber lawyer, noted for her work on high-profile data breaches, and as a published authority on cyber security. In Melbourne, Robert Gregory is an experienced commercial lawyer, acting for government and corporate clients across technology and media sectors. Brendan Tomlinson advises on information technology transactions of all types and sizes. The practice particularly stands out for its strength in government and public sector work.

Praxisleiter:

Sonia Sharma; Katherine Armytage; Rob Gregory


Weitere Kernanwälte:

Brendan Tomlinson; Ooma Khurana


Referenzen

‚Providing highly capable support with great responsiveness.‘

‚Brendan Tomlinson is engaged, focused on value and scope, pragmatic, experienced and highly competent.‘

‚A strong team legally, and it is clear the team works well together. The team are engaged and interested in the matter, and it shows in their dedication to providing legal services.‘

Kernmandanten

Sony


Diageo


Philips


Sydney Airport


Deutsche Bank


Deloitte


Aristocrat Technologies


Lendlease


Mirvac


Greencross (Petbarn)


ORIX


Macquarie Technology


Melbourne City Mission


South East Water


City of Monash


Department of Health


Digital Transformation Agency


Department of Defence


Swinburne University of Technology


HMD Global (Nokia)


Camp Australia


Department of Health and Ageing


Department of Social Services


Services Australia


Department of Education


Department of Employment and Workplace Relations


Australian Bureau of Statistics


Office of National Data Commissioner


Department of Finance


Australian Competition and Consumer Commission


Australian Federal Police


Department of Veterans’ Affairs


NSW Department of Customer Service


Cancer Institute


NSW Health


Transport for NSW


Iberdrola Australia Limited


Essential Energy


Federation University


Sydney Festival


Black Dog Institute


Racing Victoria


Dymocks


Richmond Football Club


Department of Finance: Digital ID


Optus


AGL


St Vincents Hospital


Nissan


DLA Piper

DLA Piper’s team frequently assists clients with data regulatory issues, particularly on cross-border transfers, supported by its data governance methodology. The team is particularly focused on data protection, but has growing expertise in cyber security incident training and response. Melbourne-based Tim Lyons leads the firm’s Australian intellectual property and technology group, bringing to the team over 20 years’ experience advising on data protection and privacy legislation. He is supported by John Fogarty, an experienced litigator specialising in Privacy Act regulatory enforcement matters. Sarah Birkett oversees the data, privacy and cyber team, with extensive experience in both Australia and the UK. Nicholas Boyle departed in October 2024.

Praxisleiter:

Tim Lyons


Weitere Kernanwälte:

Sarah Birkett; John Fogarty


Referenzen

‚On the cutting edge of legal developments in this space. Deep knowledge of our business. Very responsive and commercial.‘

Kernmandanten

Royal Automobile Club of Queensland Limited (RACQ)


Rimes Technologies Corporation


Office of the Australian Information Commissioner


Thales Australia


Haval Motors Australia Pty Ltd


Piper Alderman

Piper Alderman's team provides advice on all aspects of data, privacy, and information security compliance, both domestically and internationally. Tim Clark co-heads the team from Melbourne, advising clients in the IT and health sectors on data protection and privacy compliance. In Sydney, fellow co-head Andrea Beatty is part of the financial services and fintech group, bringing to the table over 20 years’ experience in privacy, regulatory compliance, breach remediation, and corporate governance. Craig Subocz manages data security and privacy matters, including policy development, employee procedures, and training, while Jamin Li assists clients with compliance and privacy complaints.

Praxisleiter:

Tim Clark; Andrea Beatty


Weitere Kernanwälte:

Craig Subocz; Jamin Li


Referenzen

‚Practical and responsive advice. The firm has easily moulded to suit our style.‘

‚Craig Subocz is an excellent lawyer with great technical know-how, but also an easy style and easy to understand communication style. He delivers on time and offers more than expected within the stated fee.‘

‚The team provide pragmatic, commercial advice that is strongly tailored to our business’s needs.‘

Kernmandanten

Australian Settlements Limited


Highlight-Mandate


  • Assisting Australian Settlements Limited with relevant data protection and privacy considerations while preparing a master service agreement for ASL’s customers.

Colin Biggers & Paisley

The cyber security and data protection team at Colin Biggers & Paisley provides a wide range of advice on cyber incidents, data privacy, and technology-related risk. The team supports clients across the insurance, professional services, health, education, infrastructure, and government spheres. Katherine Jones leads the team from Sydney, and brings to bear 18 years’ experience in commercial litigation. Morgan Lane contributes corporate, commercial, and technology expertise, advising on cross-border transactions, technology procurement, and privacy.

Praxisleiter:

Katherine Jones


Weitere Kernanwälte:

Morgan Lane; Lana Remedi


Referenzen

‚Outstanding professional service, exemplary advice, always available, complete understanding of the issues and pragmatic/practical methodology to address same.‘

‚Outstanding knowledge of the subject matter, practical and effective advice addressing issues.‘

‚The team provided highly practical solutions and were able to lead implementation of a range of other service providers seamlessly. Katherine Jones is approachable, charismatic and highly knowledgeable. She also is highly skilled in engaging with C suite execs impactfully. These elements set the team apart from other firms.‘

Kernmandanten

FIIG Securities Limited


Tiger Hold Co Pty Ltd


Brydens Lawyers


Atlantic & Peninsula Australia Pty Limited


Urban Caravans


Salta Properties


Highlight-Mandate


  • Advising Brydens Lawyers on incident response and legal advice following a ransomware attack.
  • Aiding Tiger Hold Co Pty Ltd (Funlab) in managing a significant ransomware incident and securing its network across Australia, New Zealand, and the USA.
  • Representing Atlantic & Peninsula Australia Pty Limited (A&P) in the incident response to a ransomware attack, including implications for GDPR compliance.

Dentons

Dentons‘ practice is jointly led by Michael Park, who brings to bear 30 years’ experience with particular expertise in digital transformation projects, and Robyn Chatwood, who co-heads the Australian technology sector group – both of whom are based in Melbourne – and Sydney-based Ben Allen, who heads the firm’s global compliance and investigations team. The group advises clients across technology-rich and emerging sectors including education, healthcare, and energy. Matthew Hennessy departed in March 2025.

Praxisleiter:

Michael Park; Robyn Chatwood; Ben Allen


Weitere Kernanwälte:

Antonia Hudson


Kernmandanten

Transurban


Acusensus


Angle Auto Finance Pty Ltd


Aristocrat


LG


enVista


Alibaba


Gartner


McDonald’s


Amazon Web Services


Rabobank


PayPal, Inc.


QBE Insurance (Australia) Limited


Hertz Australia


Avis Budget Group, Inc.


Highlight-Mandate


  • Aiding Transurban in reviewing its data governance framework and document retention policy.
  • Assisting Acusensus, an ASX-listed company with global operations, with privacy, surveillance and commercial matters relating to traffic infringement cameras, CCTV and workplace surveillance tools.
  • Acting for Angle on a range of privacy and credit reporting projects.

Herbert Smith Freehills Kramer LLP

Herbert Smith Freehills Kramer LLP has a strong practice in data protection, privacy, and cyber security matters, advising on a range of issues from regulatory compliance and risk management to incident response and litigation. Department head Julian Lincoln, who is based in Melbourne, is a knowledgeable technology, data, and privacy lawyer. Kwok Tang brings to the table over 20 years’ experience in IT and telecoms transactions and co-leads the global TMT sector team.

Praxisleiter:

Julian Lincoln


Weitere Kernanwälte:

Kwok Tang


Kernmandanten

Compass Group Australia


Norton Rose Fulbright

Norton Rose Fulbright's team advises corporates, governments, and data-rich clients across the financial services, healthcare, telecoms, resources, infrastructure, and technology sectors. Sydney-based Nick Abrahams, the global co-head of the digital transformation practice, is valued for his expertise in technology procurement, data privacy, and cybersecurity. Annie Haggar departed in September 2025.

Praxisleiter:

Nick Abrahams


Kernmandanten

Australian Government


Highlight-Mandate


  • Advising an Australian government agency on privacy and information law risks for participation in a whole of government trial of Copilot for Microsoft 365.

Wotton Kearney

Wotton Kearney‘s practice integrates cyber incident response with privacy, legal, and technology services. Kieran Doyle leads the practice from Sydney, regularly handling high-profile and complex cyber incidents. Nicole Gabryk has significant experience in global insurance matters, advising on cyber incident responses and litigation arising from data breaches. Ellie Brooks assists with investigations and OAIC notifications, while Rebecca Wilson specialises in privacy, data protection, and incident response.

Praxisleiter:

Kieran Doyle


Weitere Kernanwälte:

Nicole Gabryk; Ellie Brooks; Rebecca Wilson; Carmen Yong; Jordan Chen


Referenzen

‚The breach counsel provided by the WK team in Australia has been superb. They were detailed, great privacy advisory, provided regular updates, excellent liaison with local service providers and insureds and generally a good partner to work with. I trust my back with the team on Pacific matters without worries.‘

‚I tend to work and liaise with Nicole Gabryk on Australia matters the most and she has great knowledge in the field, and is a joy to work with as well. But what makes her stand out, in my opinion, is that she is willing to work with me closely for the greater benefit of Australian clients and their security awareness. This is something I find really important and have not often seen or experienced.‘

‚The Wotton Kearney team are highly efficient at making certain they provide the support their clients need, while also maintaining high levels of professionalism when connecting with industry partners to assist their efforts on complicated matters.‘

Kernmandanten

AXA XL


Emergence


The Hospital Contribution Fund of Australia (HCF)


QBE


Canopius


TOGA Group


Beazley Group Plc


Liberty Specialty Markets (Australia)


Reward Hospitality Group


Envest Group


Highlight-Mandate


  • Advising Firstmac Ltd, a major Australian non-bank lender, on a cyberattack exposing sensitive data on the dark web.
  • Representing Wendy Wu Tours in relation to a cross-border cyber incident affecting over 5,000 individuals across Australia, New Zealand, the UK, and the EU.
  • Advised HCF, Australia’s largest not-for-profit health fund, on the development of an updated data retention and disposal standard.

A&O Shearman

The A&O Shearman team is led by Anna Gamvros, who has over 25 years’ experience in high-stakes, multi-jurisdictional technology, privacy, and cybersecurity matters across Asia and Australia, splitting her time between Sydney and Hong Kong. Ross Phillipson also has extensive experience in data protection, cybersecurity, and information governance in Australia and Europe. The team’s APAC capabilities are further strengthened by Ravi De Fonseka and Daniel Thompson, who joined from Johnson Winter Slattery in May 2024.

Praxisleiter:

Anna Gamvros


Weitere Kernanwälte:

Ross Phillipson; Ravi De Fonseka; Daniel Thompson


Kernmandanten

Mastercard


HSBC


BHP


TPG


QBE


Royal Bank of Canada


Fiserv


South32


PayPal


IMI


Olam


Acciona Energia


Acciona Geotech


Highlight-Mandate


Johnson Winter Slattery

Johnson Winter Slattery‘s team has a strong practice in data protection law, advising major Australian and international organisations on cyber incidents. Helen Clarke co-leads the team from Brisbane and is a technology, data, and cyber law expert, while Sydney-based Sophie Dawson takes the lead on privacy and data protection matters, with 20 years’ experience in data breach response issues. Together they advise clients across regulated, technology-driven sectors including healthcare, financial services, digital platforms, transport, education, and energy.

Praxisleiter:

Helen Clarke; Sophie Dawson


Weitere Kernanwälte:

Jennifer Dean; Viva Swords


Referenzen

‚Brilliant team with genuine expertise and vast experience to draw upon. They stand out in their ability to understand complex situations and then develop and apply appropriate solutions and advice. They are fantastic collaborators.‘

‚They have proven track records and have worked on some really complex and high profile engagements previously. They are warm and humble and take the time to understand our needs and tailor their services accordingly. We love working with them not only because they are brilliant but also because they are wonderful people with great integrity and customer service skills.‘

‚Working with Helen Clarke and her team at Johnson Winter Slattery has been a game-changer for our organisation. Their deep expertise in data privacy, cyber risk, and technology-driven transactions has consistently delivered strategic value, especially in navigating complex regulatory landscapes and incident response scenarios.‘

Highlight-Mandate


  • Acting as Australian legal adviser to a high-profile Asia-based global online marketplace and e-commerce company on data protection and consumer terms, including privacy compliance and reviewing internal and external documentation against Australian law requirements.
  • Advising a major Australian dental group on recommendations following a group-wide privacy audit.
  • Advising an Australian tech company on privacy policies and law reforms.

Pinsent Masons LLP

Pinsent Masons LLP‘s data and privacy team advises on complex projects, including regulation of infrastructure, global data retention, cross-border transfers, and AI deployment. The team has strength in cyber incident preparation and response, advising insured and self-insured clients on managing ransomware and extortion attacks, engaging regulators, law enforcement, and government agencies. Co-led by Veronica Scott and James Arnott in Melbourne, the team was strengthened in August 2024 by the addition of Susan Kantor, who joined from Minter Ellison, enhancing the team’s expertise in AI, incident response, and cybersecurity law.

Praxisleiter:

Veronica Scott; James Arnott


Weitere Kernanwälte:

Susan Kantor; Jason Kaye; Jey Jeyabala


Referenzen

‚The Pinsent Mason team, although relatively new, have been fantastic at providing timely and accurate advice to clients, working collaboratively with cyber industry partners to build strong relationships with regulators and law enforcement that allow for a holistic approach to cyber legal assistance. The team are highly responsive and always go above and beyond on the customer service aspect of their work.‘

‚Veronica Scott has brought with her a strong team of bright minds who are very capable of providing the necessary reassurance to a client after they have experienced a cyber attack, but also deliver the necessary news and next steps that sometimes can be a difficult conversation. The team are working hard and proving their mettle, setting high standards for how cyber attacks should be handled on the legal front.‘

‚Pinsent Masons’ data protection and cyber security practice is responsive, commercially aware, and willing to adapt to client needs. While their legal advice is solid and reliable, what sets them apart is their openness to collaboration and innovation in service delivery. They’ve been proactive in offering alternative billing models and have supported us through secondments, which has helped build trust, continuity and relationships.‘

Kernmandanten

CPA Australia Limited


Bega Group


KPMG Australia Pty Limited


EnergyAustralia


Coles Supermarkets


S.M.K Holdings Pty Ltd


Peter Berry Consultancy


Trilogy Funds


Adventist HealthCare Ltd


St Vincent’s Hospital (Melbourne) Ltd and Grampians Health


Transaction Network Services (TNS)


TaguchiMarketing Pty Ltd


Orica Australia Pty Ltd


Verra Mobility Corporation


The Hospital Contribution Fund of Australia Ltd (HCF)


Medibank Private Limited


Vicinity Centres PM Pty Ltd


Vestas Australian Wind Technology Pty Ltd


FCD Health


Lifeline Australia Limited


Monash University


MMG Australia Limited


ServiceNow Ireland Limited (ServiceNow)


XCMG


Northern Territory Primary Health Network (NT PHN)


Highlight-Mandate


  • Advising Orica on managing and uplifting its global data compliance and data retention program in response to evolving and complex intersecting regulatory obligations and business needs.
  • Assisting Canopius’ cyber insurance policyholders on its response to a range of cyber incidents, including ransomware attacks and business email compromise, that had impacted large volumes of sensitive data or resulted in invoice fraud.
  • Supporting Medibank with continuous compliance uplift and an informed response to regulatory change, and to proactively manage privacy risks in the delivery of member services and development of new technology driven health solutions.